• 200+ websites of ours using this plugin was hacked due to a vulnerability that was identified quite some time ago. It was a nightmare.

    • This topic was modified 10 months, 2 weeks ago by soji89.
Viewing 3 replies - 1 through 3 (of 3 total)
  • Please, can you specify when the hacks happened and what version you were using?

    We’ve been hacked yesterday and the logs show numerous requests of /wp-json/post-smtp/v1/get… from the attacking IP and then resetting the pass via /wp-login.php?action=lostpassword.

    Any insight on this would be much appreciated.

    Thread Starter soji89

    (@soji89)

    it was day before yesterday during the night around 11:30 BST. It’s the same modus operandi, password reset and the exposed logs were used to grab the password reset link to reset passwords.

    Plugin Author Saad Iqbal

    (@saadiqbal)

    Hi @soji89 @jaromeh ,

    I sincerely apologize for the challenges you’ve experienced with our plugin, and I understand the frustration this situation has caused for you and other WordPress developers. I want to assure you that we take this matter very seriously, and we are actively working to help our users.

    To provide some context, we are working in collaboration with renowned security research teams such as Wordfence and Patchstack WordPress Security. This partnership allows us to stay ahead of potential security vulnerabilities, and together we continuously research and address any issues that may arise.

    Regarding the lack of communication and notifications, I acknowledge that we fell short in keeping you informed, and for that, I’m truly sorry. We are taking steps to improve our communication channels to ensure that such incidents are promptly and clearly communicated to our user community in the future.

    To address the recent security vulnerability:

    We had released an urgent update (V2.8.8 – 2024-01-01) that includes a fix for the identified issue.
    Moving forward, we are implementing additional measures to enhance the security of our plugin to prevent similar occurrences.

    I understand the impact this has had on your workload, and I genuinely regret any inconvenience caused. Your feedback is invaluable, and we appreciate your commitment as a user.

    If you have any further questions or if there’s anything else we can do to assist you, please don’t hesitate to reach out. We value your feedback, and your experience is important to us.

    Best regards,
    Saad Iqbal

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Poorly maintained’ is closed to new replies.